Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Infrastructure Entitlement Management (CIEM)Medium
A large enterprise is migrating a legacy application to a multi-cloud environment. The application has complex, interwoven dependencies and requires specific network access policies for different microservices, each with its own service identity. The security team needs to ensure that only authorized service identities can communicate with specific database instances, regardless of their underlying network topology. Which CIEM capability is best suited to address this requirement efficiently?
- ALeast privilege enforcement
- BRemediation workflows
- CCloud asset inventory
- DIdentity-based microsegmentation
Show answer & explanationAnswer & explanation
Correct answer: D. Identity-based microsegmentation
Identity-based microsegmentation focuses on controlling network communication between workloads based on their identity, rather than IP addresses or network segments. This is ideal for complex, dynamic multi-cloud environments where service identities need to communicate with specific resources securely, regardless of the underlying network.
Why the other options are wrong
- A. Least privilege enforcement focuses on permissions to resources, not primarily on network communication *between* services.
- B. Remediation workflows automate fixes, they don't define communication policies.
- C. Cloud asset inventory discovers resources but doesn't manage network communication policies.
Identity-based Microsegmentation
A security approach that uses identity as the primary factor for defining and enforcing granular network access policies between workloads and services, often abstracting away underlying network constructs.
- Controls network flow based on 'who' or 'what' is communicating.
- Essential for zero-trust architectures.
- Simplifies network security in dynamic cloud environments.
Memory trick: Microsegment: Identity is the key to network walls.